Developer tools · Chmod calculator
chmod vs chown: why changing the mode is often the wrong lever
· Why it matters
chmod unix access-control
Mode bits only mean something relative to an owner and a group. This post separates the two commands and shows how to decide, from the error and the process identity, which one you actually need.
Two commands, one error — permission denied has been 'fixed' three times this month with three different chmod and chown lines
chmod and chown address different information, even when both appear near a permission error. The calculator models permission bits for owner, group and other, plus special bits. It receives no current owner or group and performs no ownership operation. A mode may therefore be translated correctly while the identity relationship remains unknown and untested.
Separate the questions first. “What does 750 permit?” is answerable: owner gets rwx, group gets r-x and other gets nothing. “Who owns this?” and “Which identity runs the process?” require external evidence. Editing a mode before resolving identity may widen the wrong class; synchronized views cannot choose between chmod and ownership changes.
Ownership first, then mode — how the kernel picks owner, group or others for a process before it looks at any bits
Class selection depends on identity, which the calculator never receives. Its owner, group and other triples are categories, not discovered accounts. It cannot know whether a process matches the owner, belongs to the file's group or falls into other. It simply renders all three permission sets from one integer; credentials require external inspection.
Identity is therefore a prerequisite for judging relevance. With mode 640, owner has read and write, group has read, and other has nothing. The conversion is certain, but the applicable triple is not. No UID, membership, container mapping or ACL enters the state. Establish those facts first, then evaluate corresponding bits.
Class selection depends on identity, which the calculator does not receive
Ownership tools change who occupies owner or group relationships, while chmod changes permissions attached to those classes. This calculator implements only chmod's side. It generates octal or symbolic chmod text and never emits chown or chgrp. It also alters no files; the path field only builds a quoted preview for external review.
Widening a mode can expose additional classes without correcting ownership. Compare 750 with 757: the latter adds other read and execute. The calculator displays that delta but cannot say whether another account benefits or ownership caused the failure. Establish owner, group and process identity externally, then grant only intended classes their required bits.
The shared-group pattern — chgrp plus setgid on the directory plus 2775 as the standard answer for two users who both need write
A shared-group workflow requires external ownership tools and policy. Preset 775 is labelled “shared with a group” because group-write is enabled. Preset 2775 adds setgid, rendering rwxrwsr-x; for directories, new files inherit the directory's group. These bit descriptions do not constitute a complete collaboration design or deployment recommendation.
The page cannot create groups, choose members, run chgrp or establish that 2775 fits a workload. It also cannot inspect default ACLs, umasks or application behavior. Treat the preset as arithmetic, not policy. Resolve ownership and membership elsewhere, then compare candidate modes while grounding the actual shared-directory design in environmental evidence.
A shared-group workflow requires external ownership tools and policy
After resolving ownership elsewhere, inspect directory mode 750. Owner receives read, write and execute; group receives read and execute; other receives nothing. Group may list and enter but not create, rename or delete entries. The calculator renders rwxr-x--- and u=rwx,g=rx,o= without inspecting an actual directory or account.
Inspect 640 separately for a regular file. It becomes rw-r-----: owner read and write, group read, and nothing for other. The page displays both results but cannot assign them recursively, identify a deployment account or choose a service group. Claiming suitability for /var/www requires workload and identity evidence absent here.
Worked example: inspect 750 and 640 after ownership is resolved elsewhere
Process identity discovery lies outside this browser tool. No source invokes ps, reads service configuration, examines container namespaces or queries account databases. The calculator cannot identify a running account or supplementary groups, so it cannot determine which permission class governs an operation. That classification requires current evidence from the responsible runtime and filesystem environment.
Once identity is externally established, review the relevant class precisely. If a process should use group access, 640 gives that class read but not write, while 660 adds group-write. This arithmetic is not a recommendation; the correct bit depends on required operations. Keep discovery and policy outside the converter, using it to prevent representation mistakes.
Process identity discovery is outside this browser tool
ACLs and container UID mapping are absent from the calculator. Its model includes three ordinary classes and special bits, but no named ACL entries, mask or namespace translation. A mode may look sufficient while another layer restricts access, or restrictive while an ACL expands it. The supplied integer alone cannot resolve either possibility.
Missing inputs limit both diagnosis and remediation. The route cannot choose among chmod, chown, ACL changes or mapping corrections. It can decode a supplied base mode and render special letters such as s, S, t and T. Treat that as one evidence layer, not proof about third-party or container access.
Takeaway: decide identity before bits — then use the Chmod calculator to make the bits exactly as wide as the identity needs
Decide identity before bits. A mode works through owner, group and other classes, but the calculator knows permissions rather than the accounts occupying them. After external inspection establishes ownership and process identity, enter a candidate and verify each intended read, write and execute flag. Comparing nearby values exposes accidental widening before commands leave the browser.
The final output remains a proposal. The page rejects malformed input, synchronizes octal and symbolic forms, explains file and directory meanings, quotes paths and generates chmod text. It cannot execute commands, change ownership, evaluate ACLs, inspect policy or test applications. Validate any proposed change on the responsible system after settling identity.